social engineering

Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics
Google's Threat Intelligence Group has identified three Russian-linked cyber espionage clusters (UNC6293, UNC7005, and UNC5976) employing sophisticated social engineering tactics. These groups exploit legitimate authentication features like OAuth and app passwords to compromise accounts of researchers, diplomats, and defense personnel. They utilize fake conference invitations, spoofed login pages, and even leverage AI-generated code for malware, posing a significant challenge to traditional security monitoring.

Inside the Modern SOC: The Identity Front Door
Attackers are increasingly leveraging compromised identities and social engineering tactics to gain initial access into corporate networks, bypassing traditional security measures. This shift means security teams must focus on identity context and behavioral analysis, rather than just login credentials, to detect and respond to threats effectively. Unified security telemetry and automated correlation are crucial for SOCs to identify sophisticated, identity-driven attacks before they escalate.

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
A sophisticated cybercrime group known as UNC6671 is employing vishing attacks, targeting employees' personal phones to steal SaaS data. The attackers impersonate IT support, tricking victims into fraudulent login portals that capture credentials and multi-factor authentication tokens. This allows them to gain access to cloud environments and applications like Microsoft 365 and Okta, deploying scripts for data exfiltration.

Levi Strauss says hackers breached employee computers, accessed corporate data
Levi Strauss & Co. has reported a cybersecurity incident where hackers gained unauthorized access to corporate data by compromising three employee-issued computers through a social engineering attack. The company stated that the breach was contained quickly, business operations were not disrupted, and there is no evidence that consumer data was affected. The investigation into the incident is ongoing, and no attackers have been identified.

AI-generated phishing texts bypass human intuition
AI can craft highly convincing spear-phishing text messages that are difficult for even experienced individuals to distinguish from legitimate communications. A demonstration showed that personalized AI-generated texts, mimicking official alerts, could easily deceive recipients, highlighting the limitations of relying on gut feelings to identify threats.

ESET tracks rise in malicious AI skills and adaptable malware
Cybercriminals are increasingly leveraging artificial intelligence and adapting existing techniques to enhance their operations, according to ESET's H1 2026 Threat Report. Attackers are utilizing AI skills for malicious purposes and incorporating generative AI into malware, exemplified by Android malware PromptSpy. Social engineering tactics like ClickFix and quishing are also evolving, while ransomware attacks persist despite a decrease in ransom payments.

3 Ways AI Powers Service Desk Attacks and How to Prevent Them
Artificial intelligence is increasingly being used by attackers to enhance service desk attacks, particularly during employee onboarding. AI tools can create more convincing impersonations, accelerate reconnaissance for personalized attacks, and scale malicious campaigns. To counter these threats, organizations need to implement stronger identity verification methods, such as secure password delivery, biometric liveness detection, and multi-factor authentication before sensitive actions are approved.

Big Brand Jobs Scam Targets Marketing Pros' Google Accounts
A sophisticated phishing campaign is targeting marketing professionals by using fake job offers from major brands. This scheme employs nested redirects to bypass detection and aims to steal Google account credentials.

How the Reddit and Discord false report scam steals accounts
Scammers are targeting users on platforms like Reddit and Discord by initiating conversations under the guise of a mistaken account report. They aim to trick victims into revealing login credentials or verification codes, or into changing their account's linked email address. The ultimate goal is to gain unauthorized access to accounts, lock users out, or extort payment by threatening account deletion or misuse.